CVE-2014-2054 Information
Feb 14, 2021
cve
Description
PHPExcel before 1.8.0 as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 does not disable external entity loading in libxml which allows remote attackers to read arbitrary files cause a denial of service or possibly have other impact via an XML External Entity (XXE) attack.
Reference
http://owncloud.org/about/security/advisories/oC-SA-2014-006/ https://github.com/PHPOffice/PHPExcel/blob/develop/changelog.txt
Share on: